AMLEGALS — Strategic Lawyering
DPDPA compliance · Rights requests

DSAR handling under DPDPA: how to receive, verify and fulfil Data Principal rights requests

Sections 11 to 14 of the DPDPA give Data Principals four rights: access and correction, erasure, grievance redressal, and nomination. Rule 14 prescribes the timelines. Handling these requests requires a documented process, identity verification, a response system and an evidence trail.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

A request form with a gold checkmark beside a timeline bar and a compliance evidence folder on a dark background
Short answer

Under the Digital Personal Data Protection Act, 2023, a Data Principal has the right to obtain a summary of the personal data being processed and the processing activities (Section 11), the right to correction and erasure (Section 12), the right to grievance redressal (Section 13), and the right to nominate another person to exercise their rights after death or incapacity (Section 14). Rule 14 of the DPDP Rules, 2025 prescribes the timelines for responding. The Data Fiduciary must acknowledge the request and respond within the prescribed period. Grievances must be resolved within the timelines in Rule 14. A Data Principal who is not satisfied with the grievance redressal may complain to the Data Protection Board (Section 13(2)).

  • Data Principal rights
  • DSAR
  • Section 11
  • Section 12
  • Section 13
  • Section 14
  • Rule 14
  • Grievance redressal
Rights
Access and summary (Section 11), correction and erasure (Section 12), grievance redressal (Section 13), nomination (Section 14)
Timelines
Prescribed by Rule 14 of the DPDP Rules, 2025
Escalation
Unsatisfied Data Principal may complain to the Data Protection Board (Section 13(2))
Penalty ceiling
Up to ₹50 crore for breach of any other provision of the Act

The four rights and their statutory basis

The DPDPA grants Data Principals four categories of rights:

Data Principal rights under the DPDPA
RightSectionWhat the Data Fiduciary must do
Access and summarySection 11Provide a summary of the personal data being processed and the processing activities, and the identities of all Data Fiduciaries and Data Processors with whom the data has been shared
Correction and erasureSection 12Correct inaccurate or misleading personal data, complete incomplete data, update personal data, and erase personal data no longer necessary for the purpose
Grievance redressalSection 13Respond to any grievance about the processing of personal data within the timelines in Rule 14
NominationSection 14Allow the Data Principal to nominate another person to exercise their rights in the event of death or incapacity

Section 15 lists the duties of Data Principals. Section 12(3) provides that erasure is subject to compliance with any law that requires retention.

The end-to-end DSAR handling process

A DSAR process must cover receipt, verification, fulfilment and evidence:

  1. 01

    Receive the request

    Provide a clear channel (email, web form, in-app) for Data Principals to submit requests. Rule 9 requires published contact details.

  2. 02

    Acknowledge and log

    Acknowledge the request within the prescribed timeline. Log the date, type of request, identity of the Data Principal and the assigned handler.

  3. 03

    Verify identity

    Confirm the identity of the Data Principal before disclosing any personal data. Use the same authentication method the Data Principal used to provide the data, or an equivalent.

  4. 04

    Locate the data

    Search all systems, vendors and processors identified in the RoPA for personal data relating to the Data Principal.

  5. 05

    Fulfil the request

    For access: prepare a summary. For correction: update the records. For erasure: delete or anonymise, and notify each Data Processor (Section 8(2)). For nomination: record the nominee.

  6. 06

    Respond to the Data Principal

    Send the response within the prescribed timeline. If the request is refused (for example, retention is required by law), state the reason.

  7. 07

    Record the evidence

    Store the request, the verification step, the actions taken, the response sent and the date. This is the evidence for an audit or a Board inquiry.

Grievance redressal and Board escalation

Section 13 gives the Data Principal the right to have any grievance about the processing of personal data addressed by the Data Fiduciary. The grievance mechanism must be accessible and the response timely.

If the Data Principal is not satisfied with the response, Section 13(2) allows the complaint to be taken to the Data Protection Board. The Board may then initiate an inquiry under Section 28.

This escalation path means the grievance process is not just an internal function. It is the first step in the enforcement chain. A well-run grievance process reduces Board complaints; a badly-run one generates them.

The evidence trail for each request

In a Board inquiry, the organisation must show how it handled rights requests. The evidence includes:

  • The request log: date, type, Data Principal identity, handler, dates of each step.
  • The verification record: how identity was confirmed.
  • The action record: what data was accessed, corrected, erased or retained, and the reason.
  • The response: the communication sent to the Data Principal, with the date.
  • The processor notification: if erasure was requested, the notification sent to each Data Processor under Section 8(2).

How AMLEGALS helps set up DSAR handling

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.

The team designs the DSAR workflow, the verification protocol, the response templates, the evidence log and the escalation procedure. For ongoing support, the DSAR handling process is covered under a compliance retainer.

Questions and answers

DSAR Handling Under DPDPA: common questions

Does the DPDPA use the term DSAR?

No. The Act refers to the rights of Data Principals in Sections 11 to 14. DSAR (Data Subject Access Request) is a widely used term from GDPR practice. The underlying concept is the same: a request by the individual to exercise a right over their personal data.

What is the timeline for responding to a rights request under DPDPA?

Rule 14 of the DPDP Rules, 2025 prescribes the timelines. The Data Fiduciary must respond within the prescribed period.

Can a Data Fiduciary refuse an erasure request?

Yes, where retention is necessary for compliance with any law (Section 12(3)). The reason must be communicated to the Data Principal.

What happens if the Data Principal is not satisfied with the response?

The Data Principal may complain to the Data Protection Board under Section 13(2). The Board may then initiate an inquiry under Section 28.

Must the Data Fiduciary notify processors when data is erased?

Yes. Section 8(2) requires the Data Fiduciary to ensure the Data Processor erases personal data upon the Data Fiduciary ceasing to process it or upon the Data Principal withdrawing consent.

Contact

Set up or review your DSAR handling process

Share your current process (if any), the volume of requests you expect and your systems landscape. The AMLEGALS data privacy team will design a workflow that meets every Section 11–14 duty.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

DSAR Handling Under DPDPA: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DSAR Handling Under DPDPA?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DSAR Handling Under DPDPA under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DSAR Handling Under DPDPA under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DSAR Handling Under DPDPA?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DSAR Handling Under DPDPA rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DSAR Handling Under DPDPA?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DSAR Handling Under DPDPA · DPDPA Exposure Assessment